Moore Technology Consulting

Moore Technology Consulting Our Managed IT services help businesses optimize their technology infrastructure.

Moore Technology Consulting provides IT solutions to the White Plains, NY area.

If you do business in New York, this regulation probably applies to you — and the deadline already passed.NYDFS 23 NYCRR...
09/01/2026

If you do business in New York, this regulation probably applies to you — and the deadline already passed.

NYDFS 23 NYCRR 500 is New York's cybersecurity regulation. It was written for financial services companies — but "financial services" in New York covers a much wider range of businesses than most people realize.

If you hold a license from the New York State Department of Financial Services — insurance agents, mortgage brokers, money transmitters, premium finance companies, budget planners — you're a "covered entity." And the 2024 amendments raised the bar significantly.

Here's what most covered businesses still don't have in place:

❌ No written cybersecurity policy reviewed and approved by the board or senior officer
❌ No designated CISO (or a documented equivalent for smaller firms)
❌ MFA not enforced on all systems that access nonpublic information
❌ No annual pe*******on testing
❌ No asset inventory of systems that touch NPI
❌ Incident response plan never written — let alone tested

The 2024 amendments added stricter deadlines for Class A companies and new requirements around encryption, vulnerability scanning, and notification timelines. The enforcement activity has increased significantly — NYDFS issued its first major penalty in 2023 and has continued.

This isn't a "get around to it" situation. If you're covered and out of compliance, the exposure is real — both regulatory and reputational.

Full breakdown on the blog — who's covered, what the 2024 amendments added, and the practical steps to close the gaps.

🔗 mooretechnologyconsulting.com/blog/nydfs-cybersecurity-regulation-what-businesses-need-to-know

DM me "COMPLY" and we'll tell you whether your current posture meets the NYDFS requirements.

📍 Moore Technology Consulting · Westport, CT · White Plains, NY
🌐 mooretechnologyconsulting.com

Your email domain is probably being spoofed right now.Not maybe. Probably.If you haven't checked your DMARC record in th...
08/25/2026

Your email domain is probably being spoofed right now.

Not maybe. Probably.

If you haven't checked your DMARC record in the last 90 days — or ever — there's a reasonable chance someone is sending emails that look exactly like they came from your domain. To your clients. To your vendors. To anyone they want.

Drop your domain into MXToolbox right now and look at the DMARC result.

If you see "No DMARC record found" — attackers can spoof you freely.
If you see "p=none" — you're monitoring but not blocking anything.
If you see "p=quarantine" — you're partially protected but spoofed mail still gets through.
If you see "p=reject" — you're properly protected.

Most small businesses in CT and NY are sitting at p=none or have nothing at all.

Here's what a spoofed email looks like from the recipient's side:

From: [email protected]
Subject: Updated wire instructions for your invoice

Completely legitimate-looking. Your logo in the signature. Your footer. Your name. The recipient has no idea it didn't come from you.

That's business email compromise — and it cost U.S. businesses $2.9 billion last year.

Fixing this takes three things:

✅ SPF record — tells receiving servers which IPs are allowed to send for your domain
✅ DKIM — cryptographically signs your outgoing mail so tampering is detectable
✅ DMARC at p=reject — enforces both and blocks anything that fails

We configure this for every client we onboard. It takes a few hours and costs nothing beyond the time to set it up correctly.

Check your domain now. If the result isn't p=reject — let's talk.

Full breakdown on the blog — the right sequence to get from p=none to p=reject without breaking your own mail delivery.

🔗 mooretechnologyconsulting.com/blog/your-email-domain-is-being-spoofed

DM me "AUDIT" and I'll check your domain configuration for free.

📍 Moore Technology Consulting · Westport, CT · White Plains, NY
🌐 mooretechnologyconsulting.com

Most businesses pick their MSP the wrong way.They go with whoever a friend recommended. Or whoever showed up first in a ...
08/21/2026

Most businesses pick their MSP the wrong way.

They go with whoever a friend recommended. Or whoever showed up first in a Google search. Or the one that sent the nicest proposal.

None of those things tell you whether the provider can actually do the job.

Here's what to ask instead — before you sign anything:

🔍 "Can you show me, right now, which of our devices are missing patches?"
If they can't pull that up in real time, they don't have real visibility into environments like yours.

🔍 "Who specifically will be my point of contact, and what's their direct number?"
If the answer is "our helpdesk team" — that's a ticket queue, not a partner.

🔍 "What's included in the base contract vs. what gets billed as extra?"
Security, backup, and MFA enforcement should be standard — not upsells.

🔍 "When was the last time you tested a full restore from backup for a client?"
This one separates real MSPs from companies that set things up and forget them.

🔍 "Can you show me a sample quarterly business review?"
A provider who doesn't review environments with clients regularly isn't managing anything — they're just reacting.

🔍 "What does your offboarding process look like?"
How they answer this tells you how seriously they treat access control — and how seriously they'd treat yours.

The right MSP answers every one of these confidently and specifically. Vague answers — or "we'd have to follow up on that" — tell you what you need to know.

Full guide on the blog including the contract red flags to watch for.

🔗 mooretechnologyconsulting.com/blog/how-to-choose-the-right-msp

DM me "MANAGED" and I'll tell you what good actually looks like for a business your size.

📍 Moore Technology Consulting · Westport, CT · White Plains, NY
🌐 mooretechnologyconsulting.com

Phishing is the  #1 way attackers get into small business networks.Not because it's sophisticated. Because it works.A co...
08/18/2026

Phishing is the #1 way attackers get into small business networks.

Not because it's sophisticated. Because it works.

A convincing email. A familiar sender name. A sense of urgency. One click. That's all it takes to hand an attacker valid credentials, an open session, or a foothold inside your network.

The good news: you don't need an enterprise security budget to dramatically reduce your exposure. The controls that make the biggest difference aren't expensive — they're just not in place.

Here's what actually moves the needle:

✅ MFA on everything — the single highest-impact control. Even if credentials are stolen, MFA stops the login. Non-negotiable.

✅ DMARC, SPF, and DKIM — properly configured email authentication stops attackers from spoofing your domain. Clients get a fake invoice that looks like it came from you. This closes that door.

✅ Security awareness training — not annual videos. Regular simulated phishing with immediate micro-training when someone clicks. Huntress SAT does this well for SMBs.

✅ Email filtering — IRONSCALES, Defender for Office, or equivalent. Catches the majority of malicious emails before they reach an inbox.

✅ A clear reporting process — your team needs to know what to do when they get a suspicious email. If they don't know where to report it, they either click it or ignore it. Both are bad.

None of these require a six-figure security budget. Most are included in what you're already paying for in Microsoft 365 — they just need to be turned on and configured correctly.

Full breakdown on the blog — including what each control costs and what it stops.

🔗 mooretechnologyconsulting.com/blog/reduce-phishing-risk-small-business

DM me "ASSESS" and we'll check where your gaps are.

📍 Moore Technology Consulting · Westport, CT · White Plains, NY
🌐 mooretechnologyconsulting.com

Your cloud bill is higher than it was a year ago.You're not imagining it — and it's probably not your provider raising p...
08/18/2026

Your cloud bill is higher than it was a year ago.

You're not imagining it — and it's probably not your provider raising prices.

It's waste. Quiet, invisible, accumulating waste that nobody's gone back to clean up.

Here's what's actually on most cloud bills we review:

💤 Servers running 24/7 for a project that ended six months ago
🗄️ Orphaned storage — old backups, snapshots, disks from deleted servers
🌙 Dev and test environments running nights, weekends, and holidays when nobody's touching them
💳 On-demand pricing for workloads you run every single day — when committed pricing would save 30%+
🙈 No tags, no ownership, no visibility — so nobody even knows what's spending what

In mid-2026, a standard 2-CPU / 8GB server runs about $30/month on AWS or Azure. Small number. Until you remember most businesses run dozens of them, around the clock, without anyone checking whether they're all still needed.

The businesses that take cloud cost management seriously cut 20–30% from their bills without touching performance or reliability.

On a $5,000/month spend that's $12,000–$18,000 back in the business. Per year. For work nobody was using.

Seven ways to fight back — right-sizing, scheduling, committed pricing, storage cleanup, budgets, tagging, and quarterly reviews — all in the full breakdown on the blog.

🔗 mooretechnologyconsulting.com/blog/cloud-bill-rising-2026-how-to-fight-it

DM me "AUDIT" and we'll take a look at what's running in your environment.

📍 Moore Technology Consulting · Westport, CT · White Plains, NY
🌐 mooretechnologyconsulting.com

Cyber insurance won't pay out if you skipped the basics.Most business owners buy a policy, file it away, and assume they...
08/11/2026

Cyber insurance won't pay out if you skipped the basics.

Most business owners buy a policy, file it away, and assume they're covered. They're not — or at least not in the way they think.

Insurers have spent the last three years tightening their requirements. What used to be a checkbox application is now a technical audit. And when a claim comes in, the first thing underwriters do is check whether you had the controls you said you had.

Here's what voids a cyber insurance claim faster than anything else:

❌ No MFA — you said you had it, the breach happened through a credential attack, it wasn't enforced
❌ No tested backups — ransomware hit, you can't recover, policy covers "restoration costs" but your backups don't work
❌ Unpatched systems — known vulnerability, no patch applied, insurer calls it negligence
❌ No incident response plan — you can't demonstrate what you did or when, claim gets disputed
❌ Shared admin credentials — attacker escalated through a shared account, policy excludes insider risk

The controls insurers require aren't arbitrary. They're the same baseline security hygiene that actually prevents incidents. The problem is most businesses treat insurance as a substitute for those controls — not a complement to them.

What cyber insurance actually covers when your controls ARE in place:

✅ Forensics and incident response costs
✅ Legal and regulatory notification requirements
✅ Business interruption losses during recovery
✅ Extortion payments (ransomware)
✅ Third-party liability if client data is exposed

The policy is the last line. The controls are the actual defense.

Full breakdown on the blog — including what to look for in a policy and the five questions to ask your broker.

🔗 mooretechnologyconsulting.com/blog/cyber-insurance-what-it-covers-and-what-it-doesnt

DM me "COMPLY" and we'll tell you whether your current security posture would hold up to an insurer's audit.

📍 Moore Technology Consulting · Westport, CT · White Plains, NY
🌐 mooretechnologyconsulting.com

Most businesses don't know what good managed IT looks like.Not because they're not paying attention — but because they'v...
08/04/2026

Most businesses don't know what good managed IT looks like.
Not because they're not paying attention — but because they've never had it.
They've had:

— A break-fix guy who answers the phone most of the time

— An internal IT person who's stretched across too many things

— A large MSP that sold them a contract and then assigned a Level 1 tech they've never met

None of that is managed IT. That's managed chaos with a monthly invoice.

Here's what good actually looks like:
📋 You know your environment. Someone can tell you exactly how many devices you have, what's patched, what's not, and why — on any given day.
🔔 Problems are caught before you feel them. Your IT provider is not waiting for your call. They're seeing the alert before your team notices anything is wrong.
🔒 Security is built in — not bolted on. MFA, endpoint protection, DMARC, backups — not upsells. Standard. Included. Already running.
📞 You know who to call. Not a 1-800 number. Not a ticket queue. A name. A person who knows your environment.
📊 You get a quarterly review. Where your environment stands. What changed. What's coming. What decisions you need to make. In plain English.

That's the bar. That's what you should be getting.
If that doesn't describe your current IT relationship — it's worth having a conversation.
We wrote a full breakdown of what good managed IT looks like for a CT or NY business — including the questions to ask any MSP before you sign anything:
🔗 https://www.mooretechnologyconsulting.com/blog/what-reliable-managed-it-support-should-feel-like
DM me "MANAGED" or just reach out directly.
📍 Moore Technology Consulting · Westport, CT · White Plains, NY

🌐 mooretechnologyconsulting.com

MFA blocks over 99% of automated credential attacks.One control. 99% of attacks stopped before they start.There is no ot...
07/28/2026

MFA blocks over 99% of automated credential attacks.
One control. 99% of attacks stopped before they start.
There is no other security investment with that return — not a firewall, not endpoint protection, not a security awareness program. Nothing comes close to MFA for pure risk reduction per dollar spent.

And yet we still find businesses in CT and NY running without it.

Here's why it keeps not happening:
🔴 "We have strong passwords" — Passwords are stolen constantly. Strength is irrelevant once they're in a breach dump.

🔴 "Our team will push back" — One phishing incident costs more than a year of MFA friction.

🔴 "We'll get to it" — Kali365. FortiBleed. Both hit businesses that were going to get to it.

🔴 "Our IT guy said it's on the list" — Lists without deadlines aren't plans.

Here's what MFA actually takes to deploy across a 20-person Microsoft 365 environment:
✅ Under 2 hours of admin time to configure

✅ Under 10 minutes per user to enroll

✅ Zero additional licensing cost on most M365 plans

✅ Can be enforced via Conditional Access in a single afternoon

We've deployed MFA for every managed client we've onboarded. It is the first thing we do — before endpoint protection, before DMARC, before anything else — because nothing else matters if someone can walk in the front door with a stolen password.

Full breakdown on our blog — including exactly what MFA does and what happens without it:
🔗 mooretechnologyconsulting.com/blog/business-case-for-mfa-2026

If your business isn't running MFA on email and every cloud service touching your data — that's the one thing to fix this week.
Not next quarter. This week.
DM me "ASSESS" and we'll check your M365 tenant MFA status for free.
📍 Moore Technology Consulting · Westport, CT · White Plains, NY

🌐 mooretechnologyconsulting.com

Connecticut has a data security law that applies to your business.Most small businesses in Fairfield County don't know i...
07/21/2026

Connecticut has a data security law that applies to your business.
Most small businesses in Fairfield County don't know it exists.
It's called the Connecticut Data Privacy Act — and its data security requirements under CT SHIELD mean that if your business collects personal information on Connecticut residents, you are legally required to implement and maintain a comprehensive information security program.
That's not optional. That's the law.
Here's what it covers:
🔒 Administrative safeguards — policies, risk assessments, employee training

🖥️ Technical safeguards — access controls, encryption, patch management, monitoring

🏢 Physical safeguards — securing devices, disposing of data properly
And here's the part most business owners miss:
You don't have to be hacked to be in violation.
You just have to be unable to demonstrate that you have a documented security program in place. An audit, a complaint, or a breach investigation can expose that gap — and the fines and remediation costs that follow are far more expensive than getting compliant.
The businesses most at risk in CT right now:
❌ Professional services firms handling client financial or personal data

❌ Healthcare-adjacent businesses collecting patient or billing information

❌ Any business using a CRM, EHR, or cloud platform storing CT resident data

We help businesses across Fairfield County build the documentation, controls, and technical safeguards to meet CT SHIELD requirements — without turning it into a six-month project.
Full breakdown on our blog — including exactly what a compliant security program looks like for a 10–50 person business:
🔗 mooretechnologyconsulting.com/blog/connecticut-businesses-ct-shield-law
DM me "COMPLY" if you want to know where your business stands.
📍 Moore Technology Consulting · Westport, CT · White Plains, NY

🌐 mooretechnologyconsulting.com

Address

44 S Broadway, Suite 100
White Plains, NY
10601

Opening Hours

Monday 9am - 5pm
Tuesday 9am - 5pm
Wednesday 9am - 5pm
Thursday 9am - 5pm
Friday 9am - 5pm

Alerts

Be the first to know and let us send you an email when Moore Technology Consulting posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Moore Technology Consulting:

Shortcuts

Share